๐Ÿ” CVE Alert

CVE-2026-85055

UNKNOWN 0.0

Twenty: Field-level read bypass

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Twenty is an open-source CRM (customer relationship management) platform. Prior to 2.22.0, field-level read permission is enforced on selected output fields but not on GraphQL or REST filter predicates. A workspace member or API key with permission to read an object but not a particular field can reference that denied field in direct filters, relation filters, or persisted view filters. The resulting totalCount and row presence reveal whether guesses match the real column, forming a boolean/count oracle that can reconstruct denied field values for records exposed by the principal's row-level policy. This issue is fixed in version 2.22.0.

CWE CWE-200 CWE-285
Vendor twentyhq
Product twenty
Published Sep 22, 2026
Stay Ahead of the Next One

Get instant alerts for twentyhq twenty

Be the first to know when new unknown vulnerabilities affecting twentyhq twenty are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

twentyhq / twenty
< 2.22.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/twentyhq/twenty/security/advisories/GHSA-v93q-4jcx-7p9m github.com: https://github.com/twentyhq/twenty/pull/22873 github.com: https://github.com/twentyhq/twenty/commit/a5108d512f754a937860bda5e0c2c40c7266e19e github.com: https://github.com/twentyhq/twenty/releases/tag/twenty/v2.22.0